MEDIUM
xpf0000
CVE published 2026-08-10
CVE-2026-69116
CVE-2026-69116 is a medium-severity vulnerability in FlyEnv versions prior to 4.18.0. The issue arises from the improper sanitization of HTML in markdown rendering and AI chat content, which can lead to the injection of malicious scripts. These scripts can execute in the Electron renderer process, potentially allowing attackers to access Node.js APIs and the filesystem. The vulnerability has been publicly [truncated]